CVE-2018-8606 describes a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) version 8, where specially crafted web requests are not properly sanitized. This medium-severity vulnerability (CVSS 5.4) requires user interaction and low privileges, with potential impacts on confidentiality and integrity. While it has a low EPSS score and FAUCET Risk Score, indicating a low likelihood of exploitation, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting limited active attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, < 8.2.3.0003CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.